NEW
Font size
WorksheetsCybersecurity Quiz
Total questions: 62
Worksheet time: 5hrs 10mins
What is a threat in the context of system security?
A harmless event with no impact on a system
Any circumstance or event with the potential to adversely affect a system
A positive change in system performance
An improvement in data security
What does spoofing involve?
Modifying data on a disk
Pretending to be something or someone other than yourself
Claiming responsibility for an action
Providing authorized information
What is the purpose of a Distributed Denial of Service (DDoS) attack?
To improve system performance
To involve multiple computers sending requests
To enhance user access
To secure data from unauthorized access
What is data destruction?
The process of creating backups
The process of destroying data so it is completely unreadable
The process of encrypting data
The process of sharing data securely
What is an inside attack?
An attack initiated by an outsider
An attack initiated by an insider within a security perimeter
An attack that occurs outside the network
An attack that enhances system security
What is social engineering primarily used for?
Building secure networks
Attacking information systems
Developing software
Enhancing user experience
What is spear phishing?
A type of malware
A type of phishing targeting specific groups
A method to secure emails
A software development technique
What is the main purpose of malware?
To enhance computer performance
To infiltrate or damage a computer system
To create backup files
To improve software usability
What is a boot-sector virus?
A virus that affects only email systems
A virus that resides in the first sector of a disk or USB drive
A virus that enhances boot speed
A virus that protects the boot sector
How does a worm differ from a virus?
Worms require user intervention to replicate
Worms do not require user intervention to self-replicate
Worms are harmless
Worms enhance system security
What is a rootkit typically used for?
To encrypt a victim's entire system
To provide a hacker privileged access to a system
To restrict data communication traffic
To protect network resources from outside threats
What does ransomware do to a victim's system?
It restricts data communication traffic
It provides privileged access to hackers
It encrypts the entire system or specific files
It allows control of access based on predefined conditions
What is the primary function of a firewall?
To encrypt a victim's entire system
To provide a hacker privileged access to a system
To restrict data communication traffic to and from a network
To allow control of access based on predefined conditions
What is the role of a proxy in a network?
To encrypt a victim's entire system
To reside between a user's computer and the Internet
To restrict data communication traffic
To provide a hacker privileged access to a system
What is a third party in a supply chain responsible for?
Encrypting a victim's entire system
Providing a product or service in support of an organization's objectives
Restricting data communication traffic
Protecting network resources from outside threats
What does Network Access Control (NAC) allow?
Encrypting a victim's entire system
Control of access based on predefined conditions
Providing a hacker privileged access to a system
Residing between a user's computer and the Internet
What is the most common authentication factor?
Something you have
Something you are
Something you know
Somewhere you are
What is a drawback of Single Sign-On (SSO)?
It simplifies user access management.
It requires multiple passwords for different servers.
If an account is compromised, a hacker can access multiple servers.
It enhances security by limiting access to one server.
What protocol allows clients to access a network remotely by connecting to a RADIUS client?
Hypertext Transfer Protocol (HTTP)
User Datagram Protocol (UDP)
File Transfer Protocol (FTP)
Simple Mail Transfer Protocol (SMTP)
What is the purpose of the Accounting phase in network security?
To encrypt user data
To log user activity and track usage
To provide user authentication
To design network architecture
What is the main focus of application security?
Enhancing user interface design
Ensuring the integrity of software
Increasing application speed
Reducing software cost
What is the process of checking code for functionality and bugs during the Testing phase called?
Debugging
Fuzzing
Compiling
Encrypting
What is a common attack that uses JavaScript to inject malicious code into a web application?
SQL Injection
Phishing
Cross site scripting (XSS)
Denial of Service (DoS)
What is the purpose of applying software patches?
To enhance the user interface
To improve application speed
To remove vulnerabilities
To increase storage capacity
What should be done to applications that are not necessary according to application hardening practices?
They should be updated regularly
They should be disabled for users
They should be encrypted
They should be backed up
What are the two levels at which files can be encrypted?
In storage and during transit
During download and upload
In RAM and ROM
In the cloud and on-premises
What does an intrusion detection system (IDS) do?
Encrypts data on the network
Detects suspicious activity and alerts administrators
Increases network speed
Monitors user activity for productivity
What is the role of a Trusted Platform Module (TPM)?
To store cryptographic keys
To increase processing speed
To manage network traffic
To provide additional storage
What is the function of BitLocker?
To compress files for storage
To perform Full Disc Encryption
To monitor network traffic
To manage user accounts
What does the NIDS analyze?
User login attempts
Network traffic
File download speeds
System boot times
What is the primary function of firewalls in cybersecurity?
To increase internet speed
To protect computer systems and networks from outside systems
To enhance graphics performance
To manage user passwords
What type of firewall is installed on a single system to protect it?
Hardware-based firewall
Network-based firewall
Software-based firewall
Cloud-based firewall
Which security zone is designed for visitors to your office location?
Private zone
Public zone
Guest zone
DMZ
What is the role of a reverse proxy?
To block all incoming traffic
To allow a system on the Internet to send a request to internal systems
To increase bandwidth
To encrypt data
What is the DMZ in network security?
A secure area for storing data
An area between two firewalls allowing selected traffic to pass
A zone for guest access
A backup server location
What is the first step to prepare for handling security incidents within an organization?
Conduct a security audit
Make sure that you have an incident response team in place
Train all employees on cybersecurity
Install the latest antivirus software
Who is the first individual to be notified of an incident?
The CEO
The IT manager
The first responder
The system administrator
What is an event in the context of cybersecurity?
A planned system update
An observable occurrence in a system and/or network
A scheduled backup
A routine security check
What does post-incident analysis involve?
Installing new software
Conducting a security drill
The postmortem analysis of an incident
Hiring new staff
What percentage of cyber-attacks could be defeated by implementing basic cyber hygiene?
50%
70%
90%
100%
What does cyber hygiene refer to?
The process of cleaning computer hardware
Practices and steps that maintain system health and improve online security
The use of antivirus software
Regularly updating social media passwords
Why is it important to periodically back up your data?
To increase internet speed
To ensure data can be recovered if lost
To reduce computer memory usage
To improve software performance
What is the starting point for all future baseline assessments?
Configuration management
Baseline configuration
Data backup
Cyber hygiene
What is the term 'site reliability' referring to?
Data backup frequency
Service availability
Cyber hygiene practices
Software updates
What is the main benefit of a full backup?
It only backs up new files
It does not clear the archive bit
It backs up all files and folders
It requires less storage space
What do incremental backups do?
Backup all data regardless of changes
Backup only new data since the last backup
Backup data and clear the archive bit
Backup data without clearing the archive bit
What is a key step in testing a disaster recovery plan?
Skipping the testing phase
Testing the plan for effectiveness
Testing only once a year
Testing without a team
What is the primary objective of COMPUSEC?
To increase data redundancy
To employ countermeasures for confidentiality, integrity, and availability
To enhance user interface design
To improve software speed
What does the concept of data integrity ensure?
Data is encrypted at all times
Data is accessible to everyone
Data received is the same as data sent
Data is stored in multiple locations
What is the purpose of patching a system?
To increase system speed
To reduce vulnerabilities and chances of attack
To add new features
To decrease system size
What is the purpose of the TEMPEST program?
To enhance user experience
To identify vulnerabilities in information systems
To increase data storage capacity
To improve network speed
What does the Red/Black Principle represent in cryptographic systems?
The combination of encrypted and plain-text information
The separation of sensitive and non-sensitive data
The meticulous separation of signals containing sensitive or classified plain-text information from those carrying encrypted information
The integration of all classified information into one system
What are the three core security disciplines in Information Protection?
Personnel Security, Industrial Security, and Cyber Security
Personnel Security, Industrial Security, and Information Security
Personnel Security, Cyber Security, and Data Security
Industrial Security, Cyber Security, and Data Security
What does the Freedom of Information Act (FOIA) provide?
The right to access classified military information
The right to request access to records from any federal agency
The right to access personal data of government employees
The right to access international security documents
What is required for an individual to access classified information?
A general interest in the information
A signed Standard Form (SF) 312 and a need to know the information
A verbal agreement with a supervisor
A temporary clearance from any federal agency
What level of protection does Top-Secret information require?
Minimal protection
Moderate protection
The highest degree of protection
No protection
What is the purpose of Operations Security (OPSEC)?
To increase the visibility of Air Force missions
To reduce the vulnerability of Air Force missions by eliminating or reducing successful adversary collection and exploitation of critical information
To enhance the public's access to Air Force mission details
To share critical information with allied forces
What is the primary objective of the COMSEC program?
To promote social media usage
To ensure the employment of measures and controls to deny unauthorized persons information derived from information systems of the United States Government
To encourage public sharing of military operations
To simplify government communication systems
What is encryption?
The process of making data easily readable
The conversion of data into a form that cannot be easily understood by unauthorized people
The deletion of data from a system
The storage of data in a secure location
What does cryptography involve?
The use of coding systems to encrypt and decrypt information
The physical destruction of data
The manual copying of data
The public sharing of information
What is the role of crypto analysis?
To create new coding systems
To protect data from unauthorized access
To break a coding system so that the information can be revealed to an unauthorized user
To encrypt data for secure transmission
What does TRANSEC aim to protect against?
Unauthorized data deletion
Interception and exploitation by means other than crypto analysis
Data duplication
Public data sharing
